Oval Definition:oval:com.ubuntu.xenial:def:201777680000000
Revision Date:2018-06-11Version:1
Title:CVE-2017-7768 on Ubuntu 16.04 LTS (xenial) - medium.
Description:The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the local system by convincing the service that it is reading a status file provided by the Mozilla Windows Updater. The Mozilla Maintenance Service executes with privileged access, bypassing system protections against unprivileged users. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2017-7768
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND Package Information
  • NOT firefox package in xenial, while related to the CVE in some way, is not affected.
  • OR NOT firefox-globalmenu package in xenial, while related to the CVE in some way, is not affected.
  • OR NOT firefox-mozsymbols package in xenial, while related to the CVE in some way, is not affected.
  • OR NOT firefox-testsuite package in xenial, while related to the CVE in some way, is not affected.
  • BACK